---
id: CVE-2026-92398
title: A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380
summary: >-
  A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by
  this issue is some unknown functionality of the file /etc/rg_config/admin of
  the component user_list_note Module. Performing a manipulation of the argument
  Nam…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-78
vendor: Ruijie
product: RG-EW3000GX
affected:
  - RG-EW3000GX EW_3.0(1)B11P380
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T18:17:19.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92398'
references:
  - url: >-
      https://github.com/FoundTL/RG-EW3000GX/blob/main/RG-EW3000GX_user_list_note.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92398'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/940182'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405550'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405550/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T17:31:21.539694Z'
ingestedAt: '2026-09-16T16:59:56.623Z'
epss: 0.03178
epssPercentile: 0.87517
---

## Overview

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
